USENIX Security2023Top-tier venue
To Cloud or not to Cloud: A Qualitative Study on Self-Hosters' Motivation, Operation, and Security Mindset
Lea Gröber, Rafael Mrowczynski, Nimisha Vijay, Daphne A. Muller, Adrian Dabrowski, Katharina Krombholz
Abstract
Despite readily available cloud services, some people decide to self-host internal or external services for themselves or their organization. In doing so, a broad spectrum of commercial, institutional, and private self-hosters take responsibility for their data, security, and reliability of their operations.
Currently, little is known about what motivates these selfhosters, how they operate and secure their services, and which challenges they face. To improve the understanding of selfhosters' security mindsets and practices, we conducted a largescale survey (N S =994) with users of a popular self-hosting suite and in-depth follow-up interviews with selected commercial, non-profit, and private users (N I =41).
We found exemplary behavior in all user groups; however, we also found a significant part of self-hosters who approach security in an unstructured way, regardless of social or organizational embeddedness. Vague catch-all concepts such as firewalls and backups dominate the landscape, without proper reflection on the threats they help mitigate. At times, self-hosters engage in creative tactics to compensate for a potential lack of expertise or experience.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Understanding Parents' Perceptions and Practices Toward Children's Security and Privacy in Virtual RealityJiaxun Cao, Abhinaya S. B., Anupam Das, Pardis Emami NaeiniS&P 2024 · 19 citations
- Mapping the Cloud: A Mixed-Methods Study of Cloud Security and Privacy Configuration ChallengesSumair Ijaz Hashmi, Shafay Kashif, Lea Gröber, Katharina Krombholz et al.NDSS 2026 · 3 citations
- "Privacy across the boundary": Examining Perceived Privacy Risk Across Data Transmission and Sharing Ranges of Smart Home Personal AssistantsShuning Zhang, Shixuan Li, Haobin Xing, Jiarui Liu et al.CHI 2026 · 1 citation
- Towards Privacy and Security in Private Clouds: A Representative Survey on the Prevalence of Private Hosting and Administrator CharacteristicsLea Gröber, Simon Lenau, Rebecca Weil, Elena Groben et al.USENIX Security 2024 · 1 citation
Builds on5
- Don't You Know That You're Toxic: Normalization of Toxicity in Online GamingNicole A. Beres, Julian Frommel, Elizabeth Reid, Regan L. Mandryk et al.CHI 2021 · 235 citations
- "If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPSKatharina Krombholz, Karoline Busse, Katharina Pfeffer, Matthew Smith et al.S&P 2019 · 105 citations
- Helping Users Automatically Find and Manage Sensitive, Expendable Files in Cloud StorageMohammad Taha Khan, Christopher Tran, Shubham Singh, Dimitri Vasilkov et al.USENIX Security 2021 · 16 citations
- KondoCloud: Improving Information Management in Cloud Storage via Recommendations Based on File SimilarityWill Brackenbury, Andrew M. McNutt, Kyle Chard, Aaron J. Elmore et al.UIST 2021 · 2 citations
- Security at the End of the Tunnel: The Anatomy of VPN Mental Models Among Experts and Non-Experts in a Corporate ContextVeroniek Binkhorst, Tobias Fiebig, Katharina Krombholz, Wolter Pieters et al.USENIX Security 2022
Related papers
- "All of them claim to be the best": Multi-perspective study of VPN users and VPN providersReethika Ramesh, Anjali Vyas, Roya EnsafiUSENIX Security 2023
- Behind the Curtain: How Shared Hosting Providers Respond to Vulnerability NotificationsGiada Stivala, Rafael Mrowczynski, Maria Hellenthal, Giancarlo PellegrinoS&P 2026
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin et al.CCS 2016 · 89 citations
- Understanding Home Router Configuration Habits & AttitudesJunjian Ye, Xavier de Carné de Carnavalet, Lianying Zhao, Lifa Wu et al.CHI 2025 · 1 citation
- Herding Vulnerable Cats: A Statistical Approach to Disentangle Joint Responsibility for Web Security in Shared HostingSamaneh Tajalizadehkhoob, Tom van Goethem, Maciej Korczynski, Arman Noroozian et al.CCS 2017 · 48 citations
